Skip to main content
Praxikon

Guideline

Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)

Date
Status
in force
Body
Autoriteit Persoonsgegevens (AP)
Reference
Staatscourant 2019, nr. 64418

What it is about

Under Article 35(4) GDPR, read with Article 57(1)(k), the Dutch DPA adopted a list of 17 types of processing for which you must carry out a DPIA in advance, such as covert investigation, blacklists, fraud prevention, credit scores, financial situation, genetic data, health data, cooperation partnerships, camera surveillance, employee monitoring, location data, communication data, internet of things, profiling, observing and influencing behaviour and biometric data. Through the consistency mechanism with the EDPB, biometrics was added. The decision was signed on 19 November 2019 and published in the Government Gazette of 27 November 2019. The list is not exhaustive: if your processing is not on it, a DPIA may still be required when the processing is likely to result in a high risk.

What this means in practice

If your processing is on the list, the starting point is that you carry out a DPIA before you begin processing. Each category states which criteria from the EDPB guidelines (WP248 rev.01) the Dutch DPA took into account, which helps you substantiate your assessment. If the processing is not on the list, you assess yourself using the nine criteria of WP248 rev.01 whether a high risk is likely.

The GDPR articles concerned

Source: Autoriteit Persoonsgegevens, documentpagina met Staatscourant PDF (stcrt-2019-64418)checked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Case law

Guidelines

Legislation in motion